Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 55 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -142,6 +142,8 @@ The TUI is selected automatically when stdout is a terminal (unless `--no-tui` o
| Key | Action |
|---|---|
| `q` / Esc | quit and flush the pcap |
| `r` | start / stop recording to the pcap (see below) |
| `f` / `Ctrl-F` | edit the capture filter (see below) |
| `↑` `↓` / `k` `j` | move the cursor through the packet list |
| `PgUp` / `PgDn` | move a page at a time |
| `g` / `G` | jump to the newest / oldest buffered packet |
Expand All @@ -157,6 +159,59 @@ pins the cursor to that packet as new ones arrive; `g` resumes following the liv
The last 2000 packets stay scrollable. Panes drop out on narrow terminals: the sidebar
below 104 columns, the detail pane below 24 rows.

### Recording

`r` toggles whether packets reach the `.pcap`. Recording starts **on**, and a badge in
the header always says which way it is: `● REC` or `○ NOT RECORDING`.

Stopping recording does not stop the capture — packets keep arriving, the table keeps
filling and the stats keep counting; they simply aren't written. That's the difference
between `r` and `p`: `p` freezes the *display*, `r` gates the *file*.

- Stopping flushes the pcap, so what's on disk is complete and openable in Wireshark
while you're still watching the live traffic.
- Starting again appends to the same file, so one run can hold several recorded
stretches with the quiet parts left out.
- `--max-file-size` only counts recorded bytes, so a run that's mostly not recording
won't trip it.
- If you never record — say you turned it off and then changed the filter — the output
file is not created or truncated at all, and the closing summary says so.

The final summary reports `recorded` alongside `packets` whenever the two differ.

### Changing the filter mid-run

`f` (or `Ctrl-F`) opens a one-line BPF editor over the packet list, pre-filled with the
filter currently in force. `Ctrl-F` again applies it — so the whole edit is one key,
type, same key.

| Key | Action |
|---|---|
| `Ctrl-F` / Enter | apply the filter and restart the capture |
| Esc | close the editor, leaving the running capture alone |
| Tab | insert the highlighted completion |
| `↑` `↓` / `Ctrl-P` `Ctrl-N` | move through the completion list |
| `←` `→`, Home / End, `Ctrl-A` / `Ctrl-E` | move the caret |
| `Ctrl-W` / `Ctrl-U` | delete the previous word / the whole line |

Completion matches the word under the caret against the BPF vocabulary — `tcp`, `udp`,
`host`, `src port`, `ip proto`, `portrange`, `less`, `greater`, and the rest — each with
a one-line reminder of its syntax. Parentheses start a fresh word, so completion keeps
working inside `(...)` groups.

The filter is compiled before it is accepted: a typo is reported inline (`✗ syntax
error`) and the editor stays open on your text. An empty expression means *no filter* —
capture everything.

Applying restarts the capture from scratch: **stats, the packet list, the throughput
history, and the `--count` / `--duration` / `--max-file-size` budgets are all reset**,
and the output pcap is overwritten as soon as the new run records a packet. Use `-o`
with a fresh path per run if you need to keep an earlier capture — or press `r` before
applying, which leaves the file alone until you record again.

Recording state is the one thing that carries across a restart: if you stopped recording
before applying, it stays stopped.

### Stop conditions

Capture ends on whichever fires first: `--count`, `--duration`, `--max-file-size`, `Ctrl-C`,
Expand Down
Loading
Loading